Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.2.9200.16384 (win8_rtm.120725-1247) 0.21%
6.2.9200.16384 (win8_rtm.120725-1247) 0.21%
6.1.7600.16385 (win7_rtm.090713-1255) 0.82%
6.1.7600.16385 (win7_rtm.090713-1255) 0.82%
6.0.6000.16386 (vista_rtm.061101-2205) 0.21%
6.0.6000.16386 (vista_rtm.061101-2205) 0.21%
5.2.3790.1830 (srv03_sp1_rtm.050324-1447) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 62.27%
5.1.2600.5512 (xpsp.080413-2105) 1.65%
5.1.2600.5512 (xpsp.080413-2105) 1.44%
5.1.2600.5512 (xpsp.080413-2105) 0.62%
5.1.2600.5512 (xpsp.080413-2105) 1.86%
5.1.2600.5512 (xpsp.080413-2105) 2.27%
5.1.2600.5512 (xpsp.080413-2105) 0.41%
5.1.2600.5512 (xpsp.080413-2105) 0.62%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 2.06%
5.1.2600.5512 (xpsp.080413-2105) 0.62%
5.1.2600.5512 (xpsp.080413-2105) 0.21%
5.1.2600.5512 (xpsp.080413-2105) 1.03%
5.1.2600.5512 (xpsp.080413-2105) 1.65%
View more

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegDeleteValueA, RegOpenKeyExA, RegCloseKey, RegSetValueExA, RegCreateKeyA, RegCreateKeyExA
kernel32.dll
lstrcpynA, lstrlenA, GetSystemDirectoryA, GetSystemWindowsDirectoryA, GetVersionExA, GetACP, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, LocalFree, CloseHandle, ResetEvent, OpenEventA, CreateProcessA, lstrcatA, GetSystemInfo, lstrcmpiA, FreeLibrary, LoadLibraryA, CreateEventA, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetModuleHandleA, GetStartupInfoA, LocalAlloc, GetProcAddress, RegisterApplicationRestart, GetModuleHandleW, GetCommandLineW, GetStartupInfoW, InterlockedCompareExchange, Sleep, InterlockedExchange
msctf.dll
TF_InitSystem, TF_GetGlobalCompartment, TF_InvalidAssemblyListCacheIfExist, TF_InvalidAssemblyListCache, TF_PostAllThreadMsg, TF_CreateCicLoadMutex, TF_UninitSystem
msctfmonitor.dll
DoMsCtfMonitor
msutb.dll
ClosePopupTipbar, GetPopupTipbar
msvcrt.dll
DllMain
user32.dll
EnumWindows, GetClassNameA, FindWindowA, PostMessageA, SetTimer, KillTimer, MsgWaitForMultipleObjects, PeekMessageA, TranslateMessage, DispatchMessageA, GetMessageA, SetWindowPos, LoadCursorA, RegisterClassExA, DefWindowProcA, PostQuitMessage, CreateWindowExA, GetSystemMetrics

CTFMON.exe

CTF Loader by Microsoft

Remove CTFMON.exe
Version:   5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
MD5:   3bcef6b66827ec0b9923d20e62d067ba
SHA1:   4398bd14f26b2bb0fec638d166ed9e13276ee6a4
SHA256:   f8004a03db14c56d5a47ba5a95d5fb7937e0df911fff5c2168e852bd6b316880
This is a Windows system installed file with Windows File Protection (WFP) enabled.

What is CTFMON.exe?

CTF Loader, a Microsoft Windows process relating to the ctfmon.exe file, which monitors active windows and provides text support for speech and handwriting recognition, keyboard, translation, and other technologies.

Overview

ctfmon.exe executes as a process with the local user's privileges. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. This version is installed on Windows XP and is compiled as a 32 bit program.

DetailsDetails

File name:ctfmon.exe
Publisher:Microsoft Corporation
Product name:CTF Loader
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\ctfmon.exe
File version:5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Product version:5.1.2600.2180
Size:15 KB (15,360 bytes)
Build date:8/4/2004 2:02 PM
Digital DNA
PE subsystem:Windows GUI
Entropy:6.118468
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'ctfmon.exe' → C:\WINDOWS\system32\ctfmon.exe
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\WINDOWS\system32\ctfmon.exe'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00193358%
0.028634%
Kernel CPU:0.00133863%
0.013761%
User CPU:0.00059495%
0.014873%
Kernel CPU time:90 ms/min
100,923,805ms/min
Memory
Private memory:972 KB
21.59 MB
Private (maximum):3.46 MB
Private (minimum):2.54 MB
Non-paged memory:972 KB
21.59 MB
Virtual memory:30.29 MB
140.96 MB
Virtual memory (peak):35.6 MB
169.69 MB
Working set:2.55 MB
18.61 MB
Working set (peak):3.46 MB
37.95 MB
Resource allocations
Threads:1
12
Handles:89
600
GUI GDI count:20
103
GUI USER count:12
49

BehaviorsProcess properties

Integrety level:Undefined
Platform:32-bit
Command line:ctfmon.exe
Owner:User

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 97.00%
Windows 7 Home Premium 1.00%
Windows Vista Home Premium 1.00%
Windows 7 Home Basic 0.50%
Windows 8 Pro with Media Center 0.50%

Distribution by countryDistribution by country

United States installs about 29.23% of CTF Loader.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 30.33%
Intel 12.30%
Toshiba 10.66%
American Megatrends 9.84%
Hewlett-Packard 6.97%
GIGABYTE 6.56%
Compaq 6.56%
ASUS 4.92%
Sahara 3.69%
Lenovo 3.28%
Gateway 2.46%
Acer 1.64%
Sony 0.82%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE